AI Detector 360

Gemini and Nano Banana Images: Detection and SynthID

By AI Detector 360 Editorial Team · · 8 min read

Photography light table with a loupe resting over a blank print beside color calibration swatches

In February 2024, OpenAI started embedding C2PA Content Credentials in the images its models produced. It was a small technical change with a large strategic message: the industry had decided the answer to synthetic media was provenance, not detection. Prove where a file came from, and you no longer need to guess from its pixels.

That bet still governs this topic, with one large complication. Gemini image detection runs into a verification asymmetry: Google's Nano Banana models carry C2PA credentials you can inspect, plus SynthID watermarking you cannot, because no public third-party API reads that mark. Practical checking means reading credentials while they survive, then falling back to multi-engine scoring and scene analysis.

Key takeaways

  • Google applies SynthID watermarking to its generative image output, and as of mid-2026 only Google's own tooling can verify that mark.
  • C2PA Content Credentials are the part you can actually inspect, and platforms strip them often enough that absence proves nothing.
  • Pixel-level classifiers degrade badly on compressed images: a leading detector missed 7 of 10 after social-media-level compression in Bellingcat testing.
  • The honest output of a Gemini check is a confidence level with reasons attached, not a verdict.

What Gemini image detection can honestly deliver

Split the question before answering it. "Was this made by Gemini?" bundles three separate claims: that the image is synthetic at all, that it came from a Google model specifically, and that whoever posted it knew. Those get progressively harder.

Synthetic or not is the question detection tools are built for, and on uncompressed files with current engines it is answerable with reasonable confidence. Which model made it is attribution, and attribution weakens fast under re-encoding. Who knew what is not a technical question in any sense, and no scanner will help you with it.

Most of the frustration people report with image checking comes from asking question one, receiving an answer to question one, and then acting as though they had an answer to questions two and three.

Put numbers on how badly that goes at scale. Bellingcat's 2023 testing found a leading image detector missed 7 of 10 AI images after social-media-level compression. Run a queue of 1,000 compressed uploads through a tool performing at that level, with 200 of them genuinely synthetic, and you surface roughly 60 and wave through about 140. If your policy treats a clean scan as clearance, you have just certified 140 images you never actually checked. If your policy treats a scan as triage, the same tool is doing useful work by pointing 60 files at a human. Identical tool, identical numbers, opposite outcomes, and the difference is entirely in the sentence your policy uses to describe what a pass means.

SynthID: strong watermark, closed door

SynthID embeds an imperceptible signal directly into pixel data. That design choice is deliberate and smart, because pixel-level marks survive things that metadata does not: re-saving, moderate cropping, format conversion, the ordinary abuse a file suffers on its way across the internet.

Then comes the part that decides everything for you. There is no public third-party API for verifying SynthID. Google's tools read it; nobody else's do. So the most durable signal attached to a Gemini image is, from where you sit, invisible.

This produces a two-tier verification world. Google can check its own output at platform scale. A picture editor, a marketplace moderator or a teacher cannot check it at all. When a tool advertises SynthID verification, it is running a trained classifier, reading C2PA metadata, or inferring from artifacts, and calling that SynthID detection is marketing rather than description.

Ask any vendor claiming SynthID support one question: does your product call a Google verification endpoint, or does it infer? The answer separates a real capability from a plausible-sounding label.

Why Google keeps the door closed

The obvious objection writes itself. If provenance is a public good, why not publish a verifier and let everyone check?

The security answer is genuinely strong, and it deserves stating properly rather than dismissing. A public verifier is also a public oracle. Anyone wanting to remove a watermark can iterate against it: alter the image, test, alter again, until the mark stops registering. That loop turns watermark removal from a research problem into a scripting exercise. Every open detector in history has been optimized against by someone.

So the closed door is defensible. It is also expensive in a way that rarely gets counted. Provenance you cannot verify is not provenance for you; it is provenance for the platform. Anyone doing independent verification work, which includes most journalism, most academic integrity work and most trust-and-safety review outside the big platforms, is left with the weaker signals.

Both things are true at once. That tension has no clean resolution in 2026, and pretending otherwise is how this field keeps overselling.

Is that image AI-generated?

Upload a picture and get classifier scores, provenance (C2PA/EXIF) checks and likely-generator attribution.

Try the AI image detector

The credentials that do reach you

C2PA is the workable half. A Content Credential is a signed manifest travelling with the file: what generated it, what edited it afterward, which entity signed each assertion. Adobe Firefly, Microsoft's imaging surfaces, OpenAI's image output since February 2024, and Google's Nano Banana models in 2026 all attach them.

When a manifest survives, it is the best evidence available to a non-platform reviewer. It is signed, it is specific, and it names a chain rather than producing a probability. Our primer on C2PA content credentials covers what a manifest holds and how signatures work.

The failure mode is delivery. Platforms routinely strip metadata during upload and re-encoding. Screenshots destroy it completely. Messaging apps compress it away. So the everyday result of a credential check is "nothing found," and that result carries no information about whether the image is real. Say it out loud every time, because people keep hearing an empty manifest as a clean bill of health or as a confession, depending on what they wanted.

A five-minute check anyone can run

  1. Get the largest original you can. Ask the sender for the file, not a forward. Right-click and save from the source, not from a search result thumbnail.
  2. Read the manifest. Check C2PA and EXIF. Note what is present and what is absent, and write both down.
  3. Reverse-search two crops. Not the whole image, which fails on any re-crop. Two distinctive regions.
  4. Scan with multiple engines. Look at region-level output and the stated confidence level rather than the headline number. AI Detector 360's image detector reports C2PA and EXIF inspection alongside likely-generator attribution, so both halves land in one report.
  5. Test the scene, not the file. Shadows, reflections, whether the place exists, whether anything in frame contradicts the caption's date.

Step two is the one people skip, and it is the only step that can return a definite answer. Steps four and five never can; they narrow uncertainty. Getting that order right matters more than which scanner you pick.

At 5 credits per image, a free account's 300 monthly credits covers about 60 checks and a Pro plan at $24.99 for 15,000 credits covers around 3,000, which is the difference between spot-checking and running a moderation queue. AI Detector 360 handles text, PDF, DOCX, image and video in the same account, so a mixed queue does not mean a mixed toolchain.

Where this actually bites

ScenarioCheck firstWhat a flag is worth
Marketplace listing photosCredentials, then seller's whole catalogPattern across images beats any single score
Newsroom reader submissionOriginal file, then sourcingNothing without a human who was there
Dating or identity verificationReverse search on two cropsHigh, because recycled images dominate
Stock or licensing purchaseSupplier attestation in writingContractual, not forensic
Student or applicant portfolioProcess evidence: layers, draftsA score alone should not stand
Insurance or claims imageryMetadata and capture consistencyEscalate to a specialist, do not decide

Notice how few rows treat the classifier score as decisive. That is not modesty, it is the shape of the evidence. A percentage tells you about statistical resemblance. Every one of these decisions turns on something else.

Work through one row properly. Elena moderates listings for a furniture marketplace and gets an escalation about a seller whose room shots look staged in a way she cannot name. She checks credentials first and finds nothing, because the images arrived through a mobile app that strips metadata. She scans and gets mid-range scores with low confidence, which is genuinely useless on its own. Then she opens the seller's other eleven listings and notices that the same corner window appears in four supposedly different apartments, at the same angle, with the same afternoon light. That last step is not detection technology. It is the thing detection technology is supposed to make time for, and it is what her decision will rest on if the seller appeals.

For supplier and contributor work, put the burden where it belongs with a line like this:

Please confirm in writing whether any AI image generation or substantial AI editing was used in the supplied files, and retain the original capture or generation file for 90 days in case verification is requested.

That sentence has settled more disputes for our customers than any detection report, because it converts a forensic argument into a contractual one.

The limits worth stating out loud

We build detection tools, so the temptation to overclaim here is real. Three things we cannot do, and neither can anyone else selling you something.

We cannot read a SynthID watermark. Nobody outside Google can. Any confidence we express about a Google-model origin comes from classifiers and provenance data, and we label it that way in the report.

We cannot give you a trustworthy accuracy figure for detecting a specific current image model. There is no independent, continuously updated public benchmark for 2026-era image generators comparable to what exists for text, and vendor numbers are typically measured on uncompressed output, which is the friendliest possible condition. Our methodology page states which conditions our confidence levels assume, and our roundup of the best AI image detectors rates competitors on whether they do the same.

And we cannot rescue a screenshot. Once an image has been through compression and metadata stripping, the evidence you want is gone, and the honest answer is a low-confidence result rather than a confident guess. The same asymmetry shapes video work, which we covered in Google Veo detection.

What is left is still worth having: signed provenance when it survives, multi-engine scoring with confidence attached, region-level detail showing where suspicion concentrates, and a downloadable report someone else can audit. Start with the free scanner and no sign-up if you want to see the shape of the output before deciding whether it fits your workflow.

Provenance was the right bet. It is just only half-delivered, and knowing which half you are holding is the actual skill.

Is that image AI-generated?

Upload a picture and get classifier scores, provenance (C2PA/EXIF) checks and likely-generator attribution.

Try the AI image detector

Frequently asked questions

Can I check a SynthID watermark myself?

Not through any public third-party service as of mid-2026. Verification runs through Google's own tooling, so an outside developer has no API to call. If a product claims to read SynthID, ask what it actually measured, because it is almost certainly measuring something else.

Do Nano Banana images always carry Content Credentials?

They are designed to, but survival is the issue rather than application. Credentials are attached at generation and then routinely stripped when the file passes through social platforms, messaging apps or a screenshot. A missing manifest tells you about the delivery path, not the origin.

Does a screenshot remove the watermark too?

A screenshot destroys the file metadata for certain. Imperceptible pixel watermarking is designed to survive more handling than metadata does, but neither one helps you directly, because you still have no public tool to read the watermark.

If credentials say the image is AI-generated, is that conclusive?

It is strong evidence of what a signing tool asserted, which is close to the best available. Manifests can in principle be forged or misapplied, so treat a valid signed credential as high confidence rather than mathematical proof.

Sources & further reading

Fair-use note: AI detection scores — from any tool, including ours — are probabilistic estimates, not proof. Never make academic, employment or legal decisions on a score alone.

Related reading